URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 196.251.70.88
Firstseen:2025-03-20 08:47:04 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-10 18:25:06http://196.251.70.88/InquiryList.txtOfflineascii base64-loader DarkVisionRAT Encoded rat abuse_ch
2025-04-10 18:25:05http://196.251.70.88/Zgoapd.wavOfflineDarkVisionRAT encrypted rat abuse_ch
2025-03-21 13:59:03http://196.251.70.88/Tpjnzovlmek.mp4Offline abuse_ch
2025-03-21 13:59:03http://196.251.70.88/Qrxzkrqclcq.mp4Offline abuse_ch
2025-03-21 13:59:03http://196.251.70.88/Phjaxdujxy.wavOffline abuse_ch
2025-03-20 08:47:07http://196.251.70.88/Iujlrtsljaz.mp4OfflineDarkVisionRAT rat abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-10 18:25:06099df524838d0a8c8fd13aa809ae7b016dd9df0ad7f6011645abe6c65ff728d4txt DarkVisionRAT
2025-04-10 18:25:05e386b7f685d1aac65a3677e6fb3c00d0149c42a7676ba1e60ed6e71e26983b36unknown  
2025-03-21 14:59:227471d4850adda928b9117787eabf481a623a8e5b7434d85b35acbff2493a4afaunknown  
2025-03-20 08:47:06f3a79a19501c0a89508394be38b1343f1e888523450fb9deaabf3f26eeabeb0bunknown